A Lingjun Virtual Private Datacenter (VPD) is a dedicated private network for a Lingjun cluster. Within a VPD, you can select an IP address range, configure a gateway, and use elastic infrastructure resources such as bare metal servers and internal-facing SLB instances.
Note: This document applies only to node instance types that require configuring Lingjun connection instances when creating a cluster.
Overview
A Lingjun CIDR block typically contains the following components:
-
Virtual Private Router (VPR): The hub of a Lingjun CIDR block. It connects subnets within the CIDR block and serves as the gateway to other networks.
-
Private CIDR block: When a Lingjun CIDR block is created, the system automatically creates a dedicated vRouter and associates it with a system route table. Each Lingjun CIDR block has only one system route table, which cannot be manually created or deleted.
-
Subnet: A subdivision of a Lingjun CIDR block that connects different Lingjun nodes. You can divide a CIDR block into one or more subnets. Subnets within the same CIDR block communicate over the internal network.
A Lingjun CIDR block is a region-level resource. It cannot span regions but is available in all zones within its region.
Create Lingjun CIDR Block
-
Log on to the Lingjun console.
-
In the left-side navigation bar, choose Network Resources > Lingjun CIDRs. Click Create Lingjun network segment.
-
Configure Lingjun CIDR block parameters.
-
Enter the Name and Node IPv4 CIDR Block for the Lingjun CIDR block. When creating a Lingjun CIDR block and subnet, we recommend using a standard private CIDR block and its subnet from the following table as the private CIDR block of a Lingjun cluster.
CIDR Block
Number of available private IP addresses (excluding system reserved IP addresses)
192.168.0.0/16
65,532
172.16.0.0/12
1,048,572
10.0.0.0/8
16,777,212
Important-
The CIDR blocks
100.64.0.0/10,224.0.0.0/4,127.0.0.0/8, and169.254.0.0/16cannot be used as the CIDR block address of a Lingjun CIDR block. -
When selecting a CIDR block, ensure it does not conflict with the CIDR blocks of other network environments to which the Lingjun cluster is to be connected, such as other user VPC networks or on-premises IDC CIDR blocks.
-
-
In the Create Lingjun Subnet section, configure the Name, Zone, and other parameters of the Lingjun subnet.
-
(Optional) Click Add to create a new Lingjun subnet under the current Lingjun CIDR block.
-
-
Click Yes to complete the creation of the Lingjun CIDR block.
View basic information about a Lingjun CIDR block
-
In the left-side navigation bar, choose Network Resources > Lingjun CIDRs .
-
Search for configured Lingjun cluster CIDR blocks by Instance ID or Instance Name.
-
View information such as Instance ID / Name, Cluster CIDR Block, and Status . In the Actions column of the corresponding instance, you can add Lingjun compute edge zones or delete Lingjun CIDR blocks.
-
Click the Instance ID/Name of the corresponding Lingjun CIDR block to view its Basic Information and Lingjun Resources .
View Lingjun CIDR Block Route Entries
-
On the Lingjun CIDRs page, click the Instance ID/Name of the corresponding Lingjun CIDR block.
-
Click the Route Entry tab to view route entry information.
Field
Description
Destination CIDR block
The destination CIDR block of the route.
Next Hop Type
The next hop type of the route. Valid types:
-
Lingjun segment
-
Lingjun connection instances
-
Lingjun HUB
Next Hop Instance
The next hop instance of the route.
Route Type
The route type. Valid types:
-
System route (SYSTEM): a route whose destination CIDR block is the current Lingjun CIDR block.
-
BGP route (BGP): a route automatically learned by the current Lingjun CIDR block through the Border Gateway Protocol (BGP) dynamic routing protocol.
Status
The status of the route.
Updated At
The time when the route entry was last updated.
-
Associate Lingjun Hub
-
In the left-side navigation bar, choose Network Resources > Lingjun CIDRs.
-
In the Lingjun Hubs column of the corresponding Instance ID/Name, click the icon
. -
On the Lingjun Hubs page, attach the target Lingjun CIDR block to a Lingjun Hub. For more information, see Create a network instance connection.
Cross-Account Authorization for Lingjun Hub
-
On the Lingjun CIDRs page, click the Instance ID/Name of the target Lingjun VPD.
-
Click the Lingjun Hub Cross-account Authorization tab to view the cross-account authorization info.
-
Click Lingjun Hub Cross-account Authorization. In the dialog box, enter the Alibaba Cloud account ID and Lingjun Hub instance ID of the peer account.
ImportantIf you grant permissions to the peer account, the peer account can load your Lingjun CIDR block instance into its Lingjun Hub and connect the peer network to your network. Proceed with caution.
Cancel Cross-account Authorization for a Lingjun Hub Instance
Before canceling the authorization, make sure that the Lingjun CIDR block is not associated with the authorized Lingjun Hub.
-
In the left-side navigation pane, choose Network Resources > Lingjun CIDRs. On the page that appears, click the ID of the target Lingjun CIDR block.
-
Click the Lingjun Hub Cross-account Authorization tab. Find the target authorization entry and click Cancel Authorization in the Actions column.
-
In the Cancel Authorization dialog box, click Yes.
Create a Lingjun subnet
-
After a Lingjun subnet is created, you cannot modify its CIDR block.
-
If the Lingjun nodes in a Lingjun subnet need to communicate with other Lingjun subnets, VPCs, or on-premises data center networks, make sure that the CIDR block of the Lingjun subnet does not conflict with the destination CIDR blocks.
A Lingjun subnet is a basic network component. Lingjun nodes cannot be deployed directly in a Lingjun CIDR block — they must belong to a subnet. The CIDR block of a subnet must be a proper subset of its parent Lingjun CIDR block. The first IP address and the last three IP addresses of each subnet are reserved by the system.
For example, if the CIDR block of a Lingjun VPD is 192.168.0.0/16, the CIDR block of a Lingjun subnet within that VPD must be a proper subset of 192.168.0.0/16, such as 192.168.0.0/17~192.168.0.0/29. If the CIDR block of a Lingjun subnet is 192.168.1.0/24, the following four IP addresses are system reserved IP addresses: 192.168.1.0, 192.168.1.253, 192.168.1.254, and 192.168.1.255.
-
In the left-side navigation bar, choose Network Resources > Lingjun Subnets, click Create Lingjun Subnet.
-
On the configuration page, set parameters such as Name and VPD for the Lingjun subnet.
-
Click Yes to complete the creation.
View basic info of a Lingjun subnet
-
In the left-side navigation bar, choose Network Resources > Lingjun Subnets.
-
Search for configured Lingjun cluster CIDR blocks by Instance ID, Instance Name.
-
View Instance ID/Name, VPD, Status, and other info.
NoteInstance ID/Name Subnets with the OOB suffix are reserved for Cloud Parallel File Storage (CPFS). Each Lingjun CIDR block reserves two subnet addresses for Cloud Parallel File Storage (CPFS).
-
Click the Instance ID/Name of the corresponding Lingjun subnet to view its Basic Information and Lingjun Resources.
Create a secondary CIDR block for a Lingjun CIDR block
If the IP addresses in a Lingjun CIDR block are insufficient for your business needs, you can add a secondary CIDR block.
Limits
-
By default, each Alibaba Cloud account can create up to three secondary CIDR blocks in each region. To increase the quota of secondary CIDR blocks, see Manage Lingjun Quotas.
-
A secondary CIDR block cannot start with 0. The mask length must be between 8 and 28 bits.
-
The following CIDR blocks cannot be used as a secondary CIDR block of a Lingjun VPD:
100.64.0.0/10,224.0.0.0/4,127.0.0.0/8, and169.254.0.0/16. -
A secondary IPv4 CIDR block cannot overlap with the primary IPv4 CIDR block or any existing secondary IPv4 CIDR blocks of a Lingjun VPD. For example, you cannot add the following CIDR blocks as secondary IPv4 CIDR blocks if the primary IPv4 CIDR block of a Lingjun VPD is
192.168.0.0/16:-
A CIDR block whose IP address range is the same as that of
192.168.0.0/16. -
A CIDR block whose IP address range is larger than that of
192.168.0.0/16, such as192.168.0.0/8. -
A CIDR block whose IP address range is smaller than that of
192.168.0.0/16, such as192.168.0.0/24.
-
Procedure
-
In the left-side navigation bar, choose Network Resources > Lingjun CIDRs.
-
In the upper-left corner of the top menu bar, select the region where the target secondary CIDR block resides.
-
On the Lingjun CIDRs page, click the Instance ID/Name of the target Lingjun CIDR block instance.
-
On the details page of the target Lingjun CIDR block instance, click the CIDR block management tab.
-
Click Add Secondary CIDR Block. In the dialog box, enter a secondary CIDR block and click Yes.
Delete a secondary CIDR block from a Lingjun CIDR block
Before deleting a secondary CIDR block, you must delete the Lingjun subnets under the secondary CIDR block.
-
In the left-side navigation bar, choose Network Resources > Lingjun CIDRs.
-
In the upper-left corner of the top menu bar, select the region where the target secondary CIDR block resides.
-
On the Lingjun CIDRs page, click the Instance ID/Name of the target Lingjun CIDR block instance.
-
On the instance details page of the target Lingjun CIDR block, click the CIDR block management tab.
-
Find the target secondary CIDR block and click Delete in the Actions column. In the dialog box, click Yes.